Описание
An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying a /../../../ Directory Traversal input to the URL's GET request while connecting to the remote server port specified during setup, an attacker can retrieve local operating system files from the remote system.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Product
- Product
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Product
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:buddho:etcd_browser:-:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00488
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
CWE-22
Связанные уязвимости
CVSS3: 7.5
github
около 2 лет назад
An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying a /../../../ Directory Traversal input to the URL's GET request while connecting to the remote server port specified during setup, an attacker can retrieve local operating system files from the remote system.
EPSS
Процентиль: 65%
0.00488
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
CWE-22